MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/5438 | vendor advisory vdb entry exploit |
http://www.iss.net/security_center/static/9816.php | patch vendor advisory vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2002-08/0074.html | patch mailing list exploit |